CSC NIST Risk Management Framework 3 — Questions and Answers
Question 1: Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture?
- Authorize
- Monitor (Correct answer)
- Implement
- Assess
Correct answer: Monitor
The Monitor step requires ongoing surveillance of security controls, system changes, and threat environment to maintain situational awareness.
Question 2: What triggers a significant change review that may require re-authorization of a system under the RMF?
- Adding a new user account
- Changing the system's IP address
- Upgrading the operating system to a new major version (Correct answer)
- Updating antivirus signature files
Correct answer: Upgrading the operating system to a new major version
Major changes that significantly alter the system's attack surface or risk profile, such as OS upgrades, typically require a significant change review or re-authorization.
Question 3: What is the concept of 'ongoing authorization' in the modern RMF?
- Authorizing a system once with no expiration date
- Continuously monitoring and authorizing systems based on real-time risk data rather than fixed review cycles (Correct answer)
- Allowing any official to authorize a system at any time
- Granting authorization based on automated scanning results alone
Correct answer: Continuously monitoring and authorizing systems based on real-time risk data rather than fixed review cycles
Ongoing authorization shifts from point-in-time assessments to a continuous process where risk decisions are based on real-time monitoring data.
Question 4: Which step in the RMF was added in Revision 2 of NIST SP 800-37 to better align security with the system development lifecycle?
- Select
- Implement
- Prepare (Correct answer)
- Monitor
Correct answer: Prepare
The Prepare step was added in SP 800-37 Rev. 2 to establish context and organizational priorities before executing the remaining RMF steps.
Question 5: What is the purpose of the common control inheritance model in the RMF?
- To allow one system to inherit another system's ATO
- To enable systems to leverage security controls implemented by a provider organization, reducing duplication (Correct answer)
- To share vulnerability scan results between systems
- To transfer risk acceptance from one AO to another
Correct answer: To enable systems to leverage security controls implemented by a provider organization, reducing duplication
Common control inheritance allows systems to leverage controls (e.g., physical security, HR policies) already implemented at an organizational level, reducing redundant implementation effort.
Question 6: A cloud service provider's infrastructure is used by a federal agency. Under RMF, who is responsible for the security of the shared infrastructure controls?
- The federal agency exclusively
- The cloud service provider for infrastructure controls they manage (Correct answer)
- The third-party auditor
- NIST directly
Correct answer: The cloud service provider for infrastructure controls they manage
Under the shared responsibility model, the cloud service provider is responsible for infrastructure-layer controls they operate, while the agency is responsible for controls within its purview.
Question 7: Which NIST publication provides guidance specifically on security and privacy controls assessment procedures used in the RMF Assess step?
- NIST SP 800-30
- NIST SP 800-53A (Correct answer)
- NIST SP 800-37
- FIPS 200
Correct answer: NIST SP 800-53A
NIST SP 800-53A provides assessment procedures and methods for evaluating the effectiveness of controls documented in NIST SP 800-53.
Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture?